logo
search
Microsoft 365 Error Codes

How to Fix Microsoft 365 Error AADSTS501209 Expired JWT Signing Key

Camila MilosovichCamila Milosovich Sep 29, 2026 868 views

Question details

The user is encountering authentication error code AADSTS501209, indicating that a JSON Web Token (JWT) signature was validated using an expired key.

How to Fix Microsoft 365 Error AADSTS501209 (Expired JWT Signing Key)
Product
Microsoft 365
Device & OS
not provided
Scenario
Attempting to sign in or authenticate an application integrated with Microsoft Entra ID.
Observed behavior
The authentication process fails, returning error AADSTS501209 because the application's configuration uses expired credentials or signing keys.
Before you start

Ensure you have Microsoft Entra ID (formerly Azure AD) administrator privileges or contact your IT administrator, as resolving this requires accessing enterprise application configurations in the Azure portal.

Solution 1Recommended

Update Application Credentials in Microsoft Entra ID

Replace the expired certificates, client secrets, or signing keys for the affected application registration.

This error originates from an application registration or authentication configuration rather than a local Microsoft Office installation issue.

1
Access Microsoft Entra admin center

Log in to the Microsoft Entra admin center or Azure portal using an administrator account.

2
Locate App Registrations

Navigate to 'Identity' in the left sidebar, expand 'Applications', click on 'App registrations', and select the application causing the error.

3
Update Certificates & Secrets

Click on 'Certificates & secrets' in the application's left menu. Review the current client secrets and certificates, and delete any that have expired.

4
Generate New Credentials

Create a new client secret or upload a valid certificate. Update the external application's configuration code to use these new credentials and test the sign-in again.

Update Application Credentials in Microsoft Entra ID
Security Warning: Never post application secrets, correlation IDs, or personal identifiers publicly when troubleshooting authentication issues.
Free Microsoft Office alternative

Switch to WPS Office for a Hassle-Free Experience

Tired of dealing with complex Microsoft 365 authentication errors and subscription issues? WPS Office offers a free, lightweight, and highly compatible alternative for your document needs without the hassle of Azure AD configurations.

  1. 1. Download WPS Office: Visit the official WPS website and click 'Download WPS Office Free'.
  2. 2. Install the Software: Run the downloaded installer and follow the on-screen instructions to complete the setup.
  3. 3. Open Your Files: Launch WPS Office and instantly open your existing Microsoft Office documents without any complex sign-in requirements.
Free and lightweight office suite with no complex cloud authentication required.Fully compatible with Microsoft Word, Excel, and PowerPoint file formats (.docx, .xlsx, .pptx).Familiar user interface makes switching from Microsoft 365 seamless.Built-in PDF editor and essential productivity tools in one single application.
microsoft office alternative - wps office

Frequently Asked Questions

What does error AADSTS501209 mean?

It indicates that an application attempting to authenticate with Microsoft Entra ID is using a JSON Web Token (JWT) signature that was validated with an expired key.

Can a standard user fix the AADSTS501209 error?

Usually, no. This error requires an IT administrator or a Microsoft Entra ID administrator to update the application's credentials, client secrets, or signing keys in the Azure portal.

Does reinstalling Microsoft Office fix AADSTS501209?

No. This is an authentication and application configuration issue on the server side, not a problem with the local Office installation. Reinstalling desktop applications will not resolve it.

Where do I find the correlation ID for my support ticket?

The correlation ID and timestamp are usually displayed directly on the error screen when the AADSTS501209 authentication failure occurs. You can copy these details directly from the prompt.